CHINA
Since August 2017
Pillar Cross-border data policies |
Indicator Infrastructure requirement
Guiding Opinions on Encouraging and Regulating the Development of Internet Rental Bicycles (交通运输部等10部门关于鼓励和规范互联网 租赁自行车发展的指导意见)
According to Section 13 of the Guiding Opinions on Encouraging and Regulating the Development of Internet Rental Bicycles, companies offering internet-based bicycle rental services are required to establish domestic servers and store operational data collected within China.
Coverage Internet rental bicycle services
Sources
- https://web.archive.org/web/20220819131018/http://www.gov.cn/xinwen/2017-08/03/content_5215640.htm
- https://web.archive.org/web/20241202143415/https://digitalpolicyalert.org/event/12168-adopted-guiding-opinions-on-encouraging-and-regulating-the-development-of-internet-rental-bicycles
- https://web.archive.org/web/20231204231748/https://ecipe.org/blog/didi-what-brussels-learns-from-chinas-crackdown-on-ride-hailing-apps/#_ftn30
- Show more...
CHINA
Since May 2024, entry into force in October 2024
Pillar Cross-border data policies |
Indicator Infrastructure requirement
Interim Measures for Data Security Management of Accounting Firms (财政部 国家网信办关于印发《会计师事务所数据安全管理暂行办法》的通知)
Art. 13 of the "Interim Measures for Data Security Management of Accounting Firms" mandates that audit working papers produced by accounting firms must be stored within the territory of the People's Republic of China, in accordance with relevant regulations. Encryption devices are required to be installed domestically, managed and maintained by local teams, with encryption keys likewise retained within national borders. Pursuant to Art. 19, any transfer of audit working papers abroad must receive prior approval, and accounting firms are obliged to establish a tiered review mechanism governing such exports, alongside implementing comprehensive responsibilities for data security management and control. In addition, in accordance with Art. 14, accounting firms must establish a data backup system to ensure the continued access, retrieval, and use of relevant audit working papers in the event of disruption or restriction to audit-related application systems due to external technical factors.
Coverage Accounting firms
Sources
- https://web.archive.org/web/20250426014906/https://www.cac.gov.cn/2024-05/10/c_1717011564369521.htm
- https://web.archive.org/web/20250426015020/https://digitalpolicyalert.org/event/19863-implemented-interim-measures-for-data-security-management-of-accounting-firms-including-data-localisation-measures
- https://web.archive.org/web/20250426015507/https://www.dandreapartners.com/china-introduces-new-data-compliance-rules-for-accounting-firms/
- Show more...
CHINA
Since October 2020
Pillar Cross-border data policies |
Indicator Conditional flow regime
Amendment to the Information Security Technology – Personal Information Security Specification (GB/T 35273-2020) (信息安全技术-个人信息安全规范》(GB/T 35273-2020)修正案)
Section 9.2.i of the "Amendment to the Information Security Technology – Personal Information Security Specification" provides that where personal biometric information must not be shared or transferred unless actually essential for business needs, in which case the personal information subject must be separately informed of the purpose, types of biometrics involved, identification of the recipient and its data security capacity and the personal information subject consent must be explicitly obtained.
Coverage Horizontal
Sources
- https://web.archive.org/web/20231227001129/https://digichina.stanford.edu/work/information-security-technology-guidelines-for-personal-information-protection-on-public-and-commercial-service-informati...
- https://web.archive.org/web/20240712200613/https://www.dlapiperdataprotection.com/system/modules/za.co.heliosdesign.dla.lotw.data_protection/functions/handbook.pdf?country-1=CN
- https://web.archive.org/web/20231128172929/http://papers.ssrn.com/sol3/papers.cfm?abstract_id=2280037
- https://web.archive.org/web/20200727022639/http://law.emory.edu/elj/content/volume-64/issue-3/articles/data-nationalism.html
- https://web.archive.org/web/20211025231401/http://www.insideprivacy.com/international/china/china-releases-national-standard-for-personal-information-collected-over-information-systems-industr/
- Show more...
CHINA
Since August 2021, entry into force in November 2021
Since March 2024
Since March 2024
Pillar Cross-border data policies |
Indicator Conditional flow regime
Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法)
Provisions on Promoting and Regulating the Cross-Border Flow of Data (促进和规范数据跨境流动规定)
Provisions on Promoting and Regulating the Cross-Border Flow of Data (促进和规范数据跨境流动规定)
Under Art. 40 of the Personal Information Protection Law (PIPL), personal information handlers who process personal data exceeding the thresholds stipulated by regulatory authorities, as well as operators of critical information infrastructure, are required to store the personal information they collect and generate within the territory of China. If it is genuinely necessary for a personal information handler to transfer personal information abroad, specific regulatory requirements must be satisfied. In accordance with Art. 38 of the PIPL and Arts. 7 and 8 of the Provisions on Promoting and Regulating the Cross-Border Flow of Data, personal information handlers seeking to provide or transfer personal data outside of China must meet one of the following conditions:
1. Obtain approval through a security assessment conducted by the Cyberspace Administration of China (CAC), applicable if any of the following criteria are met: the handler is a critical information infrastructure operator; the handler (not classified as a critical information infrastructure operator) has, since 1 January of the current year, cumulatively provided the personal information of 1,000,000 individuals or sensitive personal information of 10,000 individuals to overseas recipients; the handler seeks to transfer personal information classified as important data or otherwise containing important data outside China.
2. Satisfy requirements through either of the following mechanisms: enter into the standard contract formulated by the CAC with the overseas data recipient; or obtain personal information protection certification from professional institutions in accordance with CAC rules. This applies when the handler is not a critical information infrastructure operator; or intends to transfer non-sensitive personal information of more than 100,000 but less than 1,000,000 individuals, or sensitive personal information of fewer than 10,000 individuals, on a cumulative basis, since 1 January of the current year.
Notwithstanding the above requirements, the outbound transfer of personal information, excluding important data, is exempt from these provisions under Arts. 3, 4, and 5 of the Provisions if the transfer arises from the following circumstances:
- International trade, cross-border transportation, academic collaboration, transnational manufacturing, marketing, or similar activities that do not involve personal or important data.
- Exporting personal information collected or generated outside China and then processed in China, provided no domestic personal information collected within China is included.
- Transfers necessary for the performance of contracts involving the data subject, such as cross-border shopping, payments, travel bookings, visa applications, or similar services.
- Employee-related data transfers for implementing human resources management under employment policies or collective labour agreements.
- Transfers required to protect the life, health, or property security of individuals in emergencies.
- Transfers involving non-sensitive personal information of fewer than 100,000 individuals on a cumulative basis by handlers who are not critical information infrastructure operators since 1 January of the current year.
Additionally, Arts. 38, 39, 41, 53, and 55 of the PIPL impose further obligations on personal information handlers seeking to transfer personal data outside China, including:
- Demonstrating a legitimate business or operational need for the cross-border transfer.
- Implementing measures to ensure that overseas recipients process the data in compliance with the protection standards set out in the PIPL.
- Providing adequate prior notification to individuals and obtaining their explicit consent.
- Securing approval from the relevant Chinese authorities for transfers to foreign judicial or law enforcement agencies.
- Establishing local representatives or agencies within China for overseas recipients who do not have a local entity and are classified as personal information handlers outside Mainland China.
- Conducting a personal information protection impact assessment before initiating a cross-border transfer.
1. Obtain approval through a security assessment conducted by the Cyberspace Administration of China (CAC), applicable if any of the following criteria are met: the handler is a critical information infrastructure operator; the handler (not classified as a critical information infrastructure operator) has, since 1 January of the current year, cumulatively provided the personal information of 1,000,000 individuals or sensitive personal information of 10,000 individuals to overseas recipients; the handler seeks to transfer personal information classified as important data or otherwise containing important data outside China.
2. Satisfy requirements through either of the following mechanisms: enter into the standard contract formulated by the CAC with the overseas data recipient; or obtain personal information protection certification from professional institutions in accordance with CAC rules. This applies when the handler is not a critical information infrastructure operator; or intends to transfer non-sensitive personal information of more than 100,000 but less than 1,000,000 individuals, or sensitive personal information of fewer than 10,000 individuals, on a cumulative basis, since 1 January of the current year.
Notwithstanding the above requirements, the outbound transfer of personal information, excluding important data, is exempt from these provisions under Arts. 3, 4, and 5 of the Provisions if the transfer arises from the following circumstances:
- International trade, cross-border transportation, academic collaboration, transnational manufacturing, marketing, or similar activities that do not involve personal or important data.
- Exporting personal information collected or generated outside China and then processed in China, provided no domestic personal information collected within China is included.
- Transfers necessary for the performance of contracts involving the data subject, such as cross-border shopping, payments, travel bookings, visa applications, or similar services.
- Employee-related data transfers for implementing human resources management under employment policies or collective labour agreements.
- Transfers required to protect the life, health, or property security of individuals in emergencies.
- Transfers involving non-sensitive personal information of fewer than 100,000 individuals on a cumulative basis by handlers who are not critical information infrastructure operators since 1 January of the current year.
Additionally, Arts. 38, 39, 41, 53, and 55 of the PIPL impose further obligations on personal information handlers seeking to transfer personal data outside China, including:
- Demonstrating a legitimate business or operational need for the cross-border transfer.
- Implementing measures to ensure that overseas recipients process the data in compliance with the protection standards set out in the PIPL.
- Providing adequate prior notification to individuals and obtaining their explicit consent.
- Securing approval from the relevant Chinese authorities for transfers to foreign judicial or law enforcement agencies.
- Establishing local representatives or agencies within China for overseas recipients who do not have a local entity and are classified as personal information handlers outside Mainland China.
- Conducting a personal information protection impact assessment before initiating a cross-border transfer.
Coverage Horizontal
Sources
- https://web.archive.org/web/20240617005345/https://www.wilmerhale.com/en/insights/client-alerts/20200324-china-issues-new-personal-information-security-specification
- https://web.archive.org/web/20220524101741/https://www.pipchina.cn/uploads/20210926/1632643529092037513.pdf
- https://web.archive.org/web/20230910032835/https://www.tc260.org.cn/upload/2020-09-18/1600432872689070371.pdf
- Show more...
CHINA
Since November 2012, entry into force in February 2013
Pillar Cross-border data policies |
Indicator Conditional flow regime
Guidelines for Personal Information Protection Within Public and Commercial Services Information Systems (公共及商用服务信息系统个人信息保护指南)
Art. 5.4.5. of the Guidelines for Personal Information Protection Within Public and Commercial Services Information Systems prohibit the transfer of personal data abroad without the express consent of the data subject, government permission or explicit regulatory approval "absent express consent of the subject of the personal information, or explicit legal or regulatory permission, or absent the consent of the competent authorities". If these conditions are not fulfilled, "the administrator of personal information shall not transfer the personal information to any overseas receiver of personal information, including any individuals located overseas or any organisations and institutions registered overseas." Although the Guidelines are a voluntary technical document, they might serve as a regulatory basis for judicial authorities and lawmakers.
Coverage Public and commercial services information systems
Sources
- https://web.archive.org/web/20231114190732/http://en.npc.gov.cn.cdurl.cn/2021-12/29/c_694559.htm
- https://web.archive.org/web/20231123130542/https://www.gov.cn/xinwen/2021-08/20/content_5632486.htm
- https://web.archive.org/web/20241202200931/https://www.cac.gov.cn/2024-03/22/c_1712776611775634.htm
- https://web.archive.org/web/20241202201136/https://www.chinalawtranslate.com/en/Provisions-on-Promoting-and-Regulating-the-Cross--Border-Flow-of-Data/
- https://www.dataguidance.com/notes/china-data-transfers
- https://web.archive.org/web/20241202201305/https://iclg.com/practice-areas/data-protection-laws-and-regulations/china
- Show more...
CHINA
N/A
Pillar Cross-border data policies |
Indicator Participation in trade agreements committing to open cross-border data flows
Lack of participation in agreements with binding commitments on data flows
China has not joined any agreement with binding commitments to open transfers of data across borders. Art. 12.15 of the Regional Comprehensive Economic Partnership (RCEP) recognises that each party may maintain its own regulatory requirements governing cross‑border transfers of information by electronic means and stipulates that such transfers shall not be restricted when undertaken for the conduct of business by a covered person; however, the article simultaneously allows parties to adopt or maintain any measures they themselves deem necessary to achieve a legitimate public policy objective, as well as any measures necessary to protect essential security interests, with the parties expressly affirming that the determination of such necessity lies solely with the implementing party and that such measures shall not be subject to dispute. It is reported that this formulation enables China to preserve its domestic data‑control regime under the rubric of national security without risking inter‑state disputes, and that the relative weakness of Chapter 12 renders its provisions largely ineffectual in facilitating the liberalisation of cross‑border data flows, particularly because the clause entrusting necessity assessments to the implementing party effectively permits any measure to be characterised as legitimate at that party’s discretion.
Coverage Horizontal
Sources
- https://web.archive.org/web/20260108205952/https://www.unilu.ch/fileadmin/fakultaeten/rf/burri/TAPED/TAPED_Burri_Vasquez_2025.xlsx
- https://web.archive.org/web/20250927032823/https://asean.org/wp-content/uploads/2024/10/Regional-Comprehensive-Economic-Partnership-RCEP-Agreement-Full-Text.pdf
- https://web.archive.org/web/20260317152539/https://moderndiplomacy.eu/2024/11/30/cross-border-data-flows-under-rcep-striking-a-balance-between-security-and-competitiveness/
- https://web.archive.org/web/20260317153111/https://www.cigionline.org/articles/digital-trade-rcep-wtos-future/
- Show more...
CHINA
Since August 2021, entry into force in November 2021
Pillar Domestic data policies |
Indicator Framework for data protection
Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法)
The Personal Information Protection Law provides a comprehensive regime of data protection in China.
Coverage Horizontal
CHINA
Since January 2019
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Banking Financial Institutions Anti-Money Laundering and Counter Terrorist Financing Management Measures
Pursuant to Art. 28 of the ¨Banking Financial Institutions Anti-Money Laundering and Counter-Terrorist Financing Management Measures¨, banking and financial institutions are prohibited from transmitting customer identification information and transaction data obtained in the course of fulfilling anti-money laundering and counter-terrorist financing obligations to entities outside the country, except where such transmission is authorised by applicable laws and administrative regulations.
Coverage Financial sector
CHINA
Since May 2019, entry into force in July 2019
Since June 2023, entry into force in July 2023
Since June 2023, entry into force in July 2023
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
P.R.C Regulation on the Management of Human Genetic Resources (中华人民共和国人类遗传资源管理条例)
Implementation Rules for the Regulations on the Management of Human Genetic Resources (人类遗传资源管理条例实施细则)
Implementation Rules for the Regulations on the Management of Human Genetic Resources (人类遗传资源管理条例实施细则)
According to the Regulation on the Management of Human Genetic Resources, the export of human genetic resources information from China is prohibited unless explicitly approved. Under Arts. 7, 8, 9, and 10, the provision of human genetic resources to foreign entities must comply with ethical principles, undergo corresponding ethical reviews, and meet the technical standards established by the scientific administrative departments of the State Council. Such actions must not compromise public health, national security, or public interests. Foreign organisations and individuals, as well as entities directly controlled by them, are prohibited from transferring China’s human genetic resources abroad.
Art. 28 stipulates that, in addition to a record filing, any provision of data to foreign parties or the permission for its use by foreign parties requires submission of a copy of the relevant data to the Office of Human Genetic Resource Administration within the Ministry of Science and Technology. A “security assessment” may also be required if the provision or use of such data could potentially affect China's public health, national security, or public interest. Art. 37 of the Implementation Rules details the categories of human genetic resources information that must undergo a national security review before being transferred or made accessible to foreign parties. Particular attention must be given to the export of genetic resources information, including that related to significant genetic families or populations from specific geographic regions, or exome sequencing and genome sequencing data involving more than 500 human subjects.
Art. 28 stipulates that, in addition to a record filing, any provision of data to foreign parties or the permission for its use by foreign parties requires submission of a copy of the relevant data to the Office of Human Genetic Resource Administration within the Ministry of Science and Technology. A “security assessment” may also be required if the provision or use of such data could potentially affect China's public health, national security, or public interest. Art. 37 of the Implementation Rules details the categories of human genetic resources information that must undergo a national security review before being transferred or made accessible to foreign parties. Particular attention must be given to the export of genetic resources information, including that related to significant genetic families or populations from specific geographic regions, or exome sequencing and genome sequencing data involving more than 500 human subjects.
Coverage Health sector
Sources
- https://web.archive.org/web/20230315001241/https://www.gov.cn/zhengce/content/2019-06/10/content_5398829.htm
- https://web.archive.org/web/20231003231012/https://www.chinalawtranslate.com/en/p-r-c-regulation-on-the-management-of-human-genetic-resources/
- https://web.archive.org/web/20230827000427/https://www.most.gov.cn/xxgk/xinxifenlei/fdzdgknr/fgzc/bmgz/202306/t20230601_186416.html
- https://web.archive.org/web/20240506151618/https://www.chinalawtranslate.com/en/Implementation-Rules-for-the-Regulations-on-the-Management-of-Human-Genetic-Resources/
- https://www.dataguidance.com/notes/china-data-transfers
- https://www.lexology.com/library/detail.aspx?g=5a4e9c9a-789a-4a6c-9daa-96bd74d0dc84
- https://web.archive.org/web/20240525172404/https://www.cov.com/-/media/files/corporate/publications/2019/06/key_takeaways_from_chinas_regulation_on_the_administration_of_human_genetic_resources.pdf
- https://web.archive.org/web/20240309222447/http://english.www.gov.cn/policies/latest_releases/2019/06/10/content_281476708945462.htm
- Show more...
CHINA
Since June 2021, entry into force in September 2021
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Data Security Law of the People’s Republic of China (中华人民共和国数据安全法)
Art. 36 of the Data Security Law stipulates that the competent authority of China shall process the request for providing any data from a foreign judicial body and law enforcement body in accordance with relevant laws and the international treaty or agreement which China has concluded or acceded to, or under the principle of equality and mutual benefit. Any organization or individual within the territory of China shall not provide any foreign judicial body or law enforcement body with any data stored within the territory of the People's Republic of China without the approval of the competent authority of China.
Coverage Horizontal
Sources
- https://web.archive.org/web/20231205204532/https://www.gov.cn/xinwen/2021-06/11/content_5616919.htm
- https://web.archive.org/web/20231212133950/https://digichina.stanford.edu/work/translation-data-security-law-of-the-peoples-republic-of-china/
- https://web.archive.org/web/20240414062320/https://www.lexology.com/library/detail.aspx?g=70ecc077-0b68-4f67-834d-58005716c9c4
- https://web.archive.org/web/20241202145408/https://www.oecd-ilibrary.org/docserver/179f718a-en.pdf?expires=1733152121&id=id&accname=guest&checksum=22F74D818E506CC25978C57894F76298
- Show more...
CHINA
Since September 2000, last amended in February 2016
Since September 2017
Since September 2017
Pillar Telecom infrastructure & competition |
Indicator Licensing restrictions to operate in the telecom market
Telecommunications Regulations of the People’s Republic of China (中华人民共和国电信条例)
Administrative Measures on Telecommunications Business Permits (电信业务经营许可管理办法)
Administrative Measures on Telecommunications Business Permits (电信业务经营许可管理办法)
Pursuant to Art. 7 of the Telecommunications Regulations, the State is required to implement a licensing regime for telecommunications enterprises in accordance with the categorisation of telecommunications services, which, as set out in the Appendix to the Regulations, includes basic telecommunications services. Art. 5.6 of the Administrative Measures on Telecommunications Business Permits further provides that the minimum registered capital for an operator conducting business within a single province, autonomous region, or centrally administered municipality is RMB 100 million (approx. USD 14.5 million), whereas operators providing services nationwide or across multiple such jurisdictions must have a minimum registered capital of RMB 1 billion (approx. USD 145 million). Under Art. 8 of the Telecommunications Regulations, basic telecommunications services are defined as the provision of public network infrastructure, public data transmission services, and basic voice communication services. It is reported that China’s restrictions on basic telecommunications services, including for example the imposition of very high capital requirements, have hindered foreign suppliers from entering the country’s basic telecommunications market.
Coverage Basic telecommunications services
Sources
- https://web.archive.org/web/20260324220926/https://www.beijing.gov.cn/zhengce/zhengcefagui/qtwj/202306/t20230609_3128623.html
- https://web.archive.org/web/20260325184217/https://www.moj.gov.cn/pub/sfbgw/flfggz/flfggzbmgz/201708/t20170803_146030.html
- https://web.archive.org/web/20260312191557/https://ustr.gov/sites/default/files/files/Press/Reports/2025NTE.pdf
- https://web.archive.org/web/20260325184713/https://datahub.itu.int/data/?i=100051&s=19296&e=CHN
- Show more...
CHINA
Since February 1996, last amended in 2024
Pillar Telecom infrastructure & competition |
Indicator Licensing restrictions to operate in the telecom market
Provisional Regulation of the People’s Republic of China for the Administration of International Networking of Computer Information Networks (中华人民共和国计算机信息网络国际联网管理暂行规定)
Arts. 8 and 9 of the "Provisional Regulation of the People’s Republic of China for the Administration of International Networking of Computer Information Networks" require access entities to obtain a licence prior to engaging in either operational or non-operational activities involving international networking, which, under Art. 3, is defined as the connection of domestic computer information networks with foreign networks for the purpose of international information exchange. Art. 6 additionally mandates that any computer information network directly engaging in international networking must rely solely on the international inbound and outbound channels provided by the national public telecommunications network; no entity or individual is permitted to establish independent channels or to utilise any alternative channels for international connectivity.
Coverage International networking
CHINA
Since February 2002
Pillar Telecom infrastructure & competition |
Indicator Signature of the WTO Telecom Reference Paper
WTO Telecom Reference Paper
China has appended the World Trade Organization (WTO) Telecom Reference Paper to its schedule of commitments.
Coverage Telecommunications sector
CHINA
N/A
Pillar Telecom infrastructure & competition |
Indicator Presence of an independent telecom authority
Lack of independent telecom authority
The Ministry of Industry and Information Technology (MIIT) acts as the telecommunications authority in the country, and therefore, there is no independence from the government in its decision-making process.
Coverage Telecommunications sector
CHINA
Since January 2011, entry into force in May 2011
Since February 2020
Since February 2020
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Yinfa No. 17/2011, Notice of the People's Bank of China on Protecting Personal Financial Information by Banking Financial Institutions (人民银行关于银行业金融机构做好个人金融信息保护工作的通知)
Personal Financial Information Protection Technical Specification (个人金融信息保护技术规范)
Personal Financial Information Protection Technical Specification (个人金融信息保护技术规范)
The "Notice of the People's Bank of China on Protecting Personal Financial Information by Banking Financial Institutions" states that the processing of personal information collected by commercial banks must be stored, handled and analysed within the territory of China, and such personal information is not allowed to be transferred overseas (paragraph 6).
The Personal Financial Information Protection Technical Specification (PFI Specification) regulates “any personal information collected, processed and stored by Financial Institutions during the provision of financial products and services" (PFI). The PFI specification requires that PFI collected or generated in mainland China is stored, processed and analysed within the territory. Further, under the PFI Specification, where there is a business need for cross-border transfer of personal financial information (PFI) and the financial institution obtains explicit consent to the transfer from the personal financial information subjects (i.e. the persons under the PFI Specification providing the data), conducts a security assessment and then supervises the offshore recipient to ensure responsible processing, storage and deletion of PFI (Section 7.1.3).
The Personal Financial Information Protection Technical Specification (PFI Specification) regulates “any personal information collected, processed and stored by Financial Institutions during the provision of financial products and services" (PFI). The PFI specification requires that PFI collected or generated in mainland China is stored, processed and analysed within the territory. Further, under the PFI Specification, where there is a business need for cross-border transfer of personal financial information (PFI) and the financial institution obtains explicit consent to the transfer from the personal financial information subjects (i.e. the persons under the PFI Specification providing the data), conducts a security assessment and then supervises the offshore recipient to ensure responsible processing, storage and deletion of PFI (Section 7.1.3).
Coverage Financial sector
Sources
- https://web.archive.org/web/20241009025357/http://www.pbc.gov.cn/english/130733/3911512/index.html
- https://web.archive.org/web/20220224002514/http://www.gov.cn/gongbao/content/2011/content_1918924.htm
- https://web.archive.org/web/20260515213935/https://www.pbc.gov.cn/zhengwugongkai/4081330/4406346/4693549/4085091/2020030414554980731.pdf
- https://web.archive.org/web/20220526214829/https://www.globaltradealert.org/state-act/7735/china-notice-on-financial-institutions-protection-over-personal-financial-information
- https://web.archive.org/web/20220303131123/https://e.linklaters.com/67/921/downloads/20200304-pboc-publishes-new-data-protection-guidelines-for-financial-institutions.pdf
- https://web.archive.org/web/20160508041800/http://uk.practicallaw.com/4-519-9017
- Show more...
